- The timeline of the accusation: what has emerged so far
- Winners and losers in the enterprise ecosystem
- SHM Studio's take: the contract nobody reads until the very end
- The construction site is still open: GDPR, NIS2, and the security supply chain
- Next moves: what an Italian SME should do today
- What nobody tells you: the cost of silent omission
A lawsuit filed in the United States accuses IBM of covering up data breaches that occurred in the mid-2010s. The accusation comes from a former internal cybersecurity executive. Furthermore, it involves two subsidiaries of the group. The news was reported by TechCrunch on June 5, 2026.
Therefore, the case raises serious questions for all organizations that rely on large enterprise vendors. In particular, Italian SMEs using IBM services — or similar enterprise-tier vendors — need to check what their contracts say about incident notification. In fact, European GDPR regulations impose precise obligations on both the data controller and the external processor. Consequently, an omission by the supplier can result in penalties for the final customer.
We at SHM Studio we constantly monitor the evolution of the cybersecurity landscape to offer SMEs a strategic take on events. In short, this case shows that due diligence on tech vendors is not an option: it's a must-have. So, it's time to review your contracts and incident response plans.
The timeline of the accusation: what has emerged so far
On June 5, 2026, TechCrunch has published a detailed investigation regarding a lawsuit involving IBM. It was filed by a former cybersecurity executive of the group. The accusation is serious: IBM allegedly covered up multiple data breaches that happened in the mid-2010s. Plus, two subsidiaries of the tech giant are involved in the investigation.
According to what has been reconstructed, the violations were allegedly never reported either to the competent authorities or to the affected customers. Therefore, the former executive chose the whistleblowing route, turning into a formal accuser. At the moment, IBM has not issued public statements that definitively confirm or deny the allegations.
Still, just filing the lawsuit has already sparked a big debate in the industry. People are talking about how often big tech companies handle incidents behind closed doors to avoid going public. So, this isn't just about IBM—it is about a risk management style that is super common among enterprise vendors.
Winners and losers in the enterprise ecosystem
In a story like this, positions are clearly divided. On one hand, the whistleblower chose to expose a systemic risk. On the other, IBM is dealing with a potentially costly reputational crisis. However, the truly vulnerable parties are elsewhere.
Enterprise clients — including Italian SMEs using IBM solutions for cloud infrastructure, security, or analytics — are the most exposed. In fact, if a breach is not reported, the client cannot activate its own containment measures. As a result, the damage multiplies over time, often without the organization even knowing it.
Similarly, IBM's competitors could gain a tactical advantage from the affair. However, it would be naive to consider it an isolated anomaly. According to an analysis by McKinsey on cyber resilience , many global organizations systematically underestimate breach detection and notification times. Therefore, the problem is structural, not individual.
Finally, supervisory authorities — in Europe, the Privacy Guarantor and national GDPR authorities — are potentially among the actors that could act most decisively following cases like this. Similarly, lawmakers could speed up the adoption of stricter rules on the cybersecurity supply chain.
SHM Studio's take: the contract nobody reads until the very end
We at SHM Studio We work daily with Italian SMEs that entrust part of their digital infrastructure to external vendors. Therefore, we know a recurring problem well: service contracts are signed, but their incident management clauses are rarely analyzed.
Specifically, there are three critical areas that every SME should check in its agreement with a tech vendor. First of all, the notification clause: within how many hours is the vendor required to report a breach? Secondly, residual liability: who is on the hook in case of a GDPR fine resulting from a vendor's omission? Finally, the right to audit: can the client company request evidence of the security measures taken?
According to the guidelines of the Italian Data Protection Authority , the data controller remains responsible even when delegating operations to an external processor. As a result, the vendor's omission doesn't clear the client of their legal liabilities. This is something many SMEs ignore until they face a formal dispute.
The construction site is still open: GDPR, NIS2, and the security supply chain
The IBM case fits into a rapidly evolving European regulatory context. In fact, the NIS2 Directive — which came into force in 2023 and is being progressively transposed by Member States — extends cybersecurity obligations also to organizations that are part of the supply chain of essential entities. Therefore, even an SME that provides services to a medium-sized company may find itself subject to incident notification and management requirements.
In addition to this, the DORA Regulation — applicable from January 2025 to the financial sector — has introduced stringent standards on digital operational resilience and ICT vendor management. However, the cultural impact of these regulations extends well beyond the financial perimeter. As a consequence, many SMEs are finding that their banking or insurance clients now require evidence of compliance even from indirect technology suppliers.
In this scenario, cybersecurity management can no longer be entirely outsourced to an external vendor without an internal control system. Therefore, we need a strategy that combines careful supplier selection, proper contracts, and the ability to respond to incidents independently. To dive deeper into these topics, the team at SHM Studio — AI services and Digital marketing supports SMEs in building a secure and compliant digital presence.
Next moves: what an Italian SME should do today
The IBM case offers a concrete opportunity to review your security posture. However, this is not purely a technical exercise. In particular, the most urgent actions are of a contractual and organizational nature.
- Review of Data Processing Agreements (DPAs): every contract with a vendor handling personal data must include explicit clauses on notification, liability, and audit rights. Therefore, it is advisable to involve a legal consultant specialized in privacy.
- Mapping of critical suppliers: not all vendors have the same level of access to corporate data. So, it is useful to classify them by criticality and check their stated security measures. Tools like the ENISA framework for NIS2 offer a structured guide.
- Incident response plan: even if the breach happens at a supplier, the client company must know how to react. In fact, authorities will also evaluate the readiness of the internal response.
- Internal training: staff managing vendor relationships must know their contractual rights and escalation procedures in the event of a reported incident.
- Management of external communication: in the event of an incident, communication to clients and stakeholders must be timely and consistent. Disorganized crisis management amplifies reputational damage. On this front, the services of strategic copywriting and LinkedIn campaigns can help build a credible narrative.
What nobody tells you: the cost of silent omission
There is one aspect of the IBM case that is rarely discussed openly. The biggest damage from an unreported breach isn't technical: it's about trust. In fact, when an organization finds out—often years later—that its data was compromised without anyone letting them know, the relationship with the vendor is beyond repair.
For an SME, this scenario has real consequences. First off, it opens up a period of uncertainty about which data was actually exposed. Then, there is the headache of telling your end customers what happened, along with all the PR risks that come with it. Plus, it could kick off a legal battle with the supplier who dropped the ball.
Therefore, the choice of tech partners cannot be based solely on price and features. Transparency in incident management must become an explicit selection criterion. For this reason, we at SHM Studio we encourage SMEs to include this aspect in their vendor evaluation checklists, alongside traditional technical parameters.
To learn more about how to structure a resilient digital strategy, you can check out our resources on web development , SEO , google ads campaigns or contact the team directly . Further insights are available in the SHM Studio blog .
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.